首页> 外文期刊>IEEE Transactions on Parallel and Distributed Systems >Transport-aware IP routers: a built-in protection mechanism to counter DDoS attacks
【24h】

Transport-aware IP routers: a built-in protection mechanism to counter DDoS attacks

机译:传输感知型IP路由器:内置的保护机制可应对DDoS攻击

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

The lack-of service differentiation and resource isolation by current IP routers exposes their vulnerability to Distributed Denial of Service (DDoS) attacks (Garber, 2000), causing a serious threat to the availability of Internet services. Based on the concept of layer-4 service differentiation and resource isolation, where the transport-layer information is inferred from the IP headers and used for packet classification and resource management, we present a transport-aware IP (tIP) router architecture that provides fine-grained service differentiation and resource isolation among different classes of traffic aggregates. The tIP router architecture consists of a fine-grained Quality-of-Service (QoS) classifier and an adaptive weight-based resource manager. A two-stage packet-classification mechanism is devised to decouple the fine-grained QoS lookup from the usual routing lookup at core routers. The fine-grained service differentiation and resource isolation provided inside the tIP router is a powerful built-in protection mechanism to counter DDoS attacks, reducing the vulnerability of Internet to DDoS attacks. Moreover, the tIP architecture is stateless and compatible with the Differentiated Service (DiffServ) infrastructure. Thanks to its scalable QoS support for TCP control segments, the tIP router supports bidirectional differentiated services for TCP sessions.
机译:当前IP路由器缺乏服务差异化和资源隔离,这使它们容易遭受分布式拒绝服务(DDoS)攻击(Garber,2000年),从而严重威胁了Internet服务的可用性。基于第4层服务区分和资源隔离的概念,其中传输层信息是从IP标头中推断出来的,并用于数据包分类和资源管理,我们提出了一种传输感知IP(tIP)路由器架构,该架构可提供出色的-不同类别的流量集合之间的服务区分和资源隔离。 tIP路由器体系结构由细粒度的服务质量(QoS)分类器和自适应的基于权重的资源管理器组成。设计了一种两阶段的分组分类机制,以将细粒度的QoS查找与核心路由器的常规路由查找分离。 tIP路由器内部提供的细粒度服务区分和资源隔离是一种强大的内置保护机制,可抵抗DDoS攻击,从而降低了Internet遭受DDoS攻击的脆弱性。此外,tIP体系结构是无状态的,并且与差分服务(DiffServ)基础结构兼容。由于其对TCP控制段的可扩展QoS支持,因此tIP路由器支持TCP会话的双向差异服务。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号